Hacking Atmosphere-NX - Custom Firmware in development by SciresM

Alklas

Active Member
Newcomer
Joined
Feb 1, 2018
Messages
30
Trophies
0
Age
52
XP
389
Country
France
hello

regarding the CFW, i don't understand why it would not be possible to have an untethered CFW.
as 'we' have control of the switch at early boot, would not that be possible to act as an officiel firmware update ? boot on fusée gelée, load a payload to remove the fimware encryption controls, update the firmware with our CFW or with a patch allowing dual boot, and have a definitely modified Switch ?
 

leerpsp

Well-Known Member
Member
Joined
Feb 22, 2014
Messages
1,742
Trophies
0
Age
33
XP
1,871
Country
United States
because this is a tethered cfw for the switch, that means the usb cable will have to be pluged in all the time or after i do the hack i can unplug it just when i restart i have too plug in usb and start all over?
 

sarkwalvein

There's hope for a Xenosaga port.
Member
Joined
Jun 29, 2007
Messages
8,512
Trophies
2
Age
41
Location
Niedersachsen
XP
11,245
Country
Germany
hello

regarding the CFW, i don't understand why it would not be possible to have an untethered CFW.
as 'we' have control of the switch at early boot, would not that be possible to act as an officiel firmware update ? boot on fusée gelée, load a payload to remove the fimware encryption controls, update the firmware with our CFW or with a patch allowing dual boot, and have a definitely modified Switch ?
I am not sure if that is the case, but probably you can't because the normal boot process requires the code to be signed.
You can't patch the bootrom (fortunately as it makes the exploit unpatchable), so you can't patch out the code signature verification under normal boot, but you can still run unsigned code that you send through USB due to a bug in the USB stack inside the bootrom code.

Of course, AFAIK.

--------------------- MERGED ---------------------------

because this is a tethered cfw for the switch, that means the usb cable will have to be pluged in all the time or after i do the hack i can unplug it just when i restart i have too plug in usb and start all over?
The latter.
 
Last edited by sarkwalvein,

Alklas

Active Member
Newcomer
Joined
Feb 1, 2018
Messages
30
Trophies
0
Age
52
XP
389
Country
France
I am not sure if that is the case, but probably you can't because the normal boot process requires the code to be signed.
You can't patch the bootrom (fortunately as it makes the exploit unpatchable), so you can't patch out the code signature verification under normal boot, but you can still run unsigned code that you send through USB due to a bug in the USB stack inside the bootrom code.

Of course, AFAIK.

--------------------- MERGED ---------------------------


The latter.

thanks for the explanation.
 

P4RI4H

Well-Known Member
Member
Joined
Mar 10, 2018
Messages
104
Trophies
0
Location
Earth
Website
www.twitter.com
XP
403
Country
United States
Soo many people are getting so bent out of shape about a tethered exploit. Yes it is a bit of a PITA to have to be tethered or have to invest in a Raspberry Pi setup, but you just gotta keep in mind that we are in the VERY early stages of this exploit here guys. Chances are a year down the road, there will be updates to this to make it self contained much like b9s or possibly even have keys that would eliminate the need to exploit every boot. Frankly, we should be glad there's such an easy exploit at all, given the XB1 and PS4 scenes, and one that will more on all current hardware regardless of fw version. PS4 anything newer than year old firmware (that is pretty much useless unless you enjoy playing offline or can afford to buy a second rug) has only "private" exploits and the XB1 scene is totally stagnant as they all are too busy drooling over the legit dev mode that from what I've seen, only has sandboxes emulators right now. We're ahead of the game here and for very little effort/cost.
 
  • Like
Reactions: andijames

sj33

Well-Known Member
Member
Joined
Oct 22, 2013
Messages
4,072
Trophies
2
XP
4,728
Country
Japan
Soo many people are getting so bent out of shape about a tethered exploit. Yes it is a bit of a PITA to have to be tethered or have to invest in a Raspberry Pi setup, but you just gotta keep in mind that we are in the VERY early stages of this exploit here guys. Chances are a year down the road, there will be updates to this to make it self contained much like b9s or possibly even have keys that would eliminate the need to exploit every boot. Frankly, we should be glad there's such an easy exploit at all, given the XB1 and PS4 scenes, and one that will more on all current hardware regardless of fw version. PS4 anything newer than year old firmware (that is pretty much useless unless you enjoy playing offline or can afford to buy a second rug) has only "private" exploits and the XB1 scene is totally stagnant as they all are too busy drooling over the legit dev mode that from what I've seen, only has sandboxes emulators right now. We're ahead of the game here and for very little effort/cost.

I'm surprised there's so much complaining - are people really so out of the loop that permenent exploits are expected to be the norm?

The Wii U exploit relied on a web server until Haxchi. So did Vita until Enso. All PS4 exploits do. Hell, iOS jailbreaks have all been semi-untethered for at least 2 years now with no change on the horizon.

People have been spoilt by how convenient the 3DS exploits were (*hax being offline, MSET, Menuhax, A9LH, B9S etc.), but the 3DS hacks were not the norm - they were special.
 

Reaga

Well-Known Member
Member
Joined
Jul 31, 2013
Messages
1,153
Trophies
1
Age
32
XP
1,432
Country
United States
I'm surprised there's so much complaining - are people really so out of the loop that permenent exploits are expected to be the norm?

The Wii U exploit relied on a web server until Haxchi. So did Vita until Enso. All PS4 exploits do. Hell, iOS jailbreaks have all been semi-untethered for at least 2 years now with no change on the horizon.

People have been spoilt by how convenient the 3DS exploits were (*hax being offline, MSET, Menuhax, A9LH, B9S etc.), but the 3DS hacks were not the norm - they were special.
It doesn't even sound that bad anyway. It sounds like it only really requires the tethered exploit at boot. I doubt sleep-mode will reset the exploit, so just keep your switch near a power-source when you're not on the go and you should be fine.
 
  • Like
Reactions: -----a and P4RI4H

Draxzelex

Well-Known Member
Member
Joined
Aug 6, 2017
Messages
19,012
Trophies
2
Age
29
Location
New York City
XP
13,393
Country
United States
People have been spoilt by how convenient the 3DS exploits were (*hax being offline, MSET, Menuhax, A9LH, B9S etc.), but the 3DS hacks were not the norm - they were special.
*gets PTSD flashbacks to beginning of 3DS hacking scene*
<-Current Gateway user
 

Red1Reaper

Asperger Dude
Member
Joined
Feb 5, 2017
Messages
339
Trophies
0
Age
27
Location
Valencia, Rafelbuñol
XP
661
Country
Spain
As far as i know, once the CFW is finished there will be no need to do tethered, i mean, the security of the switch is totally compromised whit this, soo i dont see anything that can stop the cfw from signing itself, installing itself in the nand and after that booting itself, that said, im not an expert, soo i can be wrong.

EDIT: Yeah i think i was wrong
 
Last edited by Red1Reaper,

sj33

Well-Known Member
Member
Joined
Oct 22, 2013
Messages
4,072
Trophies
2
XP
4,728
Country
Japan
As far as i know, once the CFW is finished there will be no need to do tethered, i mean, the security of the switch is totally compromised whit this, soo i dont see anything that can stop the cfw from signing itself, installing itself in the nand and after that booting itself, that said, im not an expert, soo i can be wrong.
These kinds of presumptuous posts just add to the confusion.
 

sarkwalvein

There's hope for a Xenosaga port.
Member
Joined
Jun 29, 2007
Messages
8,512
Trophies
2
Age
41
Location
Niedersachsen
XP
11,245
Country
Germany
...Yet.

Things are bound to only get better from here on out.
Unless you send the Ninja team to Nintendo HQ, I don't see how you will get it.
As you know, the Switch doesn't hold it, it doesn't know it, it is never used, not when you read a game, not when you go into eShop... never.
For verifying a signature you only need the public key, that is on the Switch, there is no reason for Nintendo to ever give anyone the private key, it doesn't get outside its HQ.
 

P4RI4H

Well-Known Member
Member
Joined
Mar 10, 2018
Messages
104
Trophies
0
Location
Earth
Website
www.twitter.com
XP
403
Country
United States
Unless you send the Ninja team to Nintendo HQ, I don't see how you will get it.
As you know, the Switch doesn't hold it, it doesn't know it, it is never used, not when you read a game, not when you go into eShop... never.
For verifying a signature you only need the public key, that is on the Switch, there is no reason for Nintendo to ever give anyone the private key, it doesn't get outside its HQ.

Preeeeettty suuure this has always been the case for every company, rever, including when lvl0 private keys were leaked for the PS3. It may not be for a long time, maybe decades, but I'm confident someone out there will release these. Disgruntled employee, hackers, changes to privacy laws, old recycled Nintendo PC dug out of a dumpster. Never can know my dude.
 

TerraPhantm

Well-Known Member
Member
Joined
Jul 27, 2007
Messages
498
Trophies
0
XP
680
Country
United States
...Yet.

Things are bound to only get better from here on out.
Even if you used every computer on the planet, it would take a few million years to factor that key. Only way around it is if they made a mistake in either key generation or signature verification (like with B9S)

Preeeeettty suuure this has always been the case for every company, rever, including when lvl0 private keys were leaked for the PS3. It may not be for a long time, maybe decades, but I'm confident someone out there will release these. Disgruntled employee, hackers, changes to privacy laws, old recycled Nintendo PC dug out of a dumpster. Never can know my dude.

As far as I know, the PS3 key was able to be calculated because Sony made a mistake and didn't randomize properly.
 
  • Like
Reactions: P4RI4H

Site & Scene News

Popular threads in this forum

General chit-chat
Help Users
  • No one is chatting at the moment.
    Y @ YuseiFD: :creep: